DataTalksClub / DataTalksClub/website
Epic: Build the automated and manual verification system
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
PM disposition
GROOMED / OPEN / P0 / VERIFICATION COORDINATION / DEPENDENCY-BLOCKED.
This is a coordination epic, not one broad engineering lane. It maps every applicable requirement in specification 10 and the current inventory/decision authority to one named producer, test, artifact, or explicitly manual gate. Its source-side children provide the deterministic harness, producer graph, and release-report consumer. It does not implement product/domain behavior, execute a data migration, contact a provider, or authorize a release.
This audit was performed on 2026-08-31 against the local remote-tracking ref origin/main at face8e4808d65afbf0374d1ced7a88079950d663, the complete #11 history, all listed coordination lanes, the current issue graph, _docs/PROCESS.md, the ten numbered specifications, and open-decisions.md. The completed scheduled regression 33361472539 is red at that SHA; the current scheduled run 33412714315 was observed in progress once and is not evidence. The older 9a491cd runs are superseded and cannot satisfy this epic.
Normative authority
- _docs/PROCESS.md, including separate engineer, independent tester, PM, merge, push, and on-call roles.
- _docs/specs/README.md and all ten numbered specifications.
- _docs/specs/10-verification-strategy.md, which is the direct verification authority.
- _docs/specs/09-migration-rollout-roadmap.md, for migration, rehearsal, rollback, and cutover boundaries.
- _docs/specs/open-decisions.md, whose current index has 21 numbered sections.
- The application-boundary and change-selective-verification contracts.
- The accepted foundations and issue-owned contracts listed below.
Outcome
Map every release-critical requirement to exactly one bounded verification destination:
- unit and service-state tests;
- backend-portable Django/database integration tests on isolated SQLite;
- contract and OpenAPI/parity tests;
- local Playwright/browser, accessibility, and screenshot evidence;
- security, privacy, redaction, and fault tests;
- infrastructure/deployment, migration, backup/restore, rollback, and operational evidence; or
- an explicitly named HUMAN, provider, protected-environment, or production gate.
Specification 10 expressly does not maintain a PostgreSQL-only application suite. RDS PostgreSQL is verified only at the exact-image deployment-migration, database-aware readiness, and deployed-smoke boundaries. Ordinary local and CI application tests use isolated SQLite through the accepted #75 harness.
Boundaries and ownership
- Tests use synthetic, redacted, project-local evidence and do not write to ordinary/shared databases or send uncontrolled email.
- #11 does not implement missing domain behavior, rewrite the adopted course platform, change URLs/SEO, activate content, execute protected-source imports, access AWS/provider/production state, or weaken a failed release gate.
- Source-only verification contracts may validate local fixtures and record required external rows as NO_GO; they never turn synthetic evidence into production authority.
- Runtime behavior, schema/data migration, application services, and management capabilities remain with their owning domain epics and issues.
- Migration execution and production-like rehearsal remain with the course/content/event rollout issues and #60/#73. Production cutover, sender/provider activation, legacy retirement, and observation remain with #74 and the separately authorized owners.
- A source commit, local candidate, issue comment, green focused test, scheduled run, or old evidence envelope is not acceptance for a different current-main identity.
Course-platform adoption authority used by verification
The course contract is adoption-first and must remain explicit in every verification producer:
- Closed #13 records adoption of the maintained course-management platform from the exact source pin 98a235283904b4ef9ad29e196298540756cf1bcc; it is not permission to mirror a moving upstream branch.
- Closed #30 owns the literal source copy, original migrations, copied-file provenance, and characterization baseline. It is not a Course-to-Cohort migration or production-like rehearsal.
- Closed #14 makes curriculum definitions Cohort-owned and keeps reusable Course family identity separate. Closed #15 requires explicit reviewed legacy edition-to-family mapping; live regex/year stripping is not an approved migration authority.
- Open #5 remains the course adoption/evolution epic. #51 owns the structural Course-to-Cohort migration after #224; #54 owns target-native registration/enrollment coordination; #60 owns the side-effect-disabled production-like course rehearsal.
- CMP changes are selectively reviewed through their own issues: #230, #231, and #234 are target-owned overlays on the fixed pin; closed #235 rejects the upstream bulk registration/correction APIs. #11 is a consumer of accepted course contracts, not a CMP synchronization lane.
- Verification must preserve the distinction between Course, Cohort, registration campaign, registration, enrollment, learner records, and historical aggregate totals. It must not treat a current campaign as a Cohort, infer mappings from a slug, or claim migration/runtime/activation from source-only checks.
Epic completion gate
All of these remain unchecked until the normal independent lifecycle proves them:
- The current Milestone-0 classification/inventory package from #72 covers all ten specifications and exactly 21 decision sections, with immutable source/spec/decision identities and no drift.
- Accepted deterministic foundations and later verification extensions are consumed at current interfaces, with fresh evidence recomputed for the candidate rather than historical evidence copied forward.
- #63, #64, #65, and #66 provide accepted current producer contracts. Required HUMAN/provider/protected-environment rows remain explicit, owned, fresh, redacted, and NO_GO while their real gates are pending.
- #76 provides the complete verification-producer graph and #77 provides the deterministic report/checksum/go-no-go consumer. Missing, stale, red, duplicate, unowned, contaminated, or mismatched evidence fails closed.
- An independent tester recomputes the exact plan and graph, validates every evidence envelope, runs the applicable gates, captures and inspects required screenshots for render-impacting work, and reports no unexplained skip or pending source-side producer.
- PM accepts the exact tester-passed identity before any child commit is created. Closure of #11 does not authorize #73 or #74, production/provider actions, or a cutover.
Delivery DAG
The authoritative coordination flow is:
Ten specifications + current 21-section decision index
+ accepted inventory inputs (#30, #34, #150, #152, #153)
-> #72 Milestone-0 classification (OPEN; source-only; not accepted)
accepted #1/#34/#35 + #75 harness
+ accepted #104/#113/#143/#146/#210/#211/#212/#213 verification extensions
+ accepted domain and infrastructure producer contracts
-> #76 verification-producer graph (OPEN; source-only; dependency-blocked)
-> #77 deterministic report consumer (OPEN; source-only; dependency-blocked)
-> #73 development rehearsal (OPEN; separately authorized, outbound-disabled)
-> #74 production cutover (OPEN; separately authorized, production NO-GO)
The current hard graph is:
#61 + #32 + #33 + #52 + #64 + #66 -> #63
#254 -> #281 -> #255
#281 -> #283 -> #257
#281 -> #285 -> #256
#255 + #256 + #257 + #258 + #282 -> #259
#255 + #256 + #257 + #258 + #259 + domain adapters -> #260
#72 + #63 + #64 + #65 + #66 + accepted domain/infra producers -> #76
#72 + #76 -> #77
#77 -> #73 -> #74
An open parent, stale candidate, ordinary CI run, scheduled regression, synthetic fixture, or issue prose is not an accepted prerequisite.
Coordination-child ledger
These are the original #11 coordination lanes and their current GitHub state:
- #1 — closed foundation and process baseline.
- #34 — closed legacy URL/link/fragment/asset/SEO manifest crawler.
- #35 — closed compatibility, redirect, link, and SEO parity gate.
- #63 — open residual security/authorization traceability; blocked on its accepted identity, management, privacy, legacy, operations, and external MFA inputs.
- #64 — open privacy coordination epic; retains human and decision; its source-only #254 and non-activating #281–#285 interfaces precede runtime children #255–#260.
- #65 — open accessibility producer/manual gate; source automation cannot satisfy its real keyboard/screen-reader/HUMAN rows.
- #75 — closed deterministic SQLite/factory/browser safety foundation.
- #76 — open producer graph and coverage coordinator; dependency-blocked.
- #77 — open deterministic release-report consumer; dependency-blocked.
- #146 — closed render-impact screenshot evidence component, explicitly under #11.
Accepted related verification extensions
These are not additional open #11 engineering lanes, and their historical green evidence is not current-main proof:
- #104 — closed change-selective CI and scheduled full-regression baseline.
- #113 — closed digest-bound ownership/evidence planning foundation.
- #143 — closed deterministic scheduled-workflow repair.
- #210 — closed smoke/core/full browser-profile foundation.
- #211 — closed ownership-metadata source-of-truth repair.
- #212 — closed top-level-app guard and selection observability.
- #213 — closed compatibility/full-Django separation.
Current blockers owned outside this epic
The current red-gate recovery is not silently absorbed into #11. Its issues retain their own scope and lifecycle: #253 (source/projection reproducibility), #261 (current-main formatting/typing/content gates), #232 and #236 (homepage/browser release-gate regressions), #279 (Spotify browser-harness denial), #280 (failed structured-component evidence), #295 (event migration inventory), and #296 (optional signup-route login rendering). Related content/browser recovery remains in #223, #270, and #271; CI critical-path/capacity work remains in #228, #238, #239, #240, and #252. None of these defects is an implicit #11 child or acceptance substitute.
Source-only, runtime, migration, and activation disposition
| Boundary | Current owner and meaning | What #11 may record |
|---|---|---|
| Source-only classification | #72 | A versioned requirement/inventory/decision classification, never a product implementation or release pass. |
| Source-only producer graph | #76, consuming #63/#64/#65/#66 and accepted domain/infra producers | Exact owner/test/artifact/freshness/redaction/no-go rows; no live check or broad cross-domain patch. |
| Source-only report consumer | #77 | Deterministic canonical report/checksum/diagnostics and synthetic negative fixtures; required real evidence stays NO_GO. |
| Runtime/domain implementation | #2–#9 and their owning children, including course #5/#51/#54 and operations #66 | References to accepted producer contracts only; no runtime mutation from this epic. |
| Migration and rehearsal | #51/#60 and #73 | Current mapping/reconciliation/rehearsal evidence only after those owners pass their own gates; no import or rollback execution here. |
| Activation/cutover | #73/#74 and separately authorized provider/AWS/production owners | A required downstream gate and its evidence contract; never authority inferred from #11. |
Lifecycle and next action
Do not dispatch #76 or #77 as a broad lane from this epic. The next source-side sequence is:
- Obtain an accepted current #72 classification package.
- Complete the blocked producer contracts and current-main recovery owned by #63/#64/#65/#66 and their children.
- Dispatch #76 as one bounded graph/coverage source lane.
- Dispatch #77 only after #72 and #76 are accepted at exact identities.
- Leave #73/#74 to their separate rehearsal/cutover owners and authority gates.
Every implementation follows engineer (uncommitted) -> independent tester (including screenshots when graph-selected) -> PM acceptance -> focused commit -> local no-ff merge/push -> on-call. The old 9a491cd verification envelopes and repeated scheduled failures are not reusable.
Labels and issue state
The title remains accurate: Epic: Build the automated and manual verification system.
Current labels remain correct and intentionally unchanged: P0, epic, testing. needs grooming, human, and decision are not added to #11: #11 coordinates the verification system, while the manual/provider/production authority belongs to the owning children and downstream phases.
#11 remains OPEN until its completion gate is met. No acceptance checkbox is inferred or checked by this audit.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with _docs/PROCESS.md and _docs/specs/10-verification-strategy.md, then inspect the dependency outputs from #72, #76, and #77. This epic is done only when current producer contracts, the verification graph, the deterministic report consumer, and independent tester gates cover the listed requirements without unexplained skips or stale evidence.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, django, playwright, postgresql, python, sqlite
- Domain
- backend, ci-cd, release, testing
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100